Senior System Security Engineer, Platform Attestation

AppleSeattle, WashingtonOn-siteFull-timeSenior, 5–8 yearsListed 59 minutes ago

Apply now

About this role

The cloudOS System Software Engineering team is at the forefront of developing secure server software and is responsible for building the Apple Silicon server platform that powers Private Cloud Compute. We own the trust boundary between the physical hardware in our data centers and the services that run on it: before a node can serve a user request, we cryptographically prove its authenticity and integrity. We are looking for an exceptional security engineer with experience architecting and developing low-level, secure software to build new technologies to support Apple’s product security and customer privacy principles.

In this role, you will be part of a team that builds and maintains system software such as kernel drivers, runtime libraries, frameworks, and daemons, and you will own the attestation architecture for the server platform. You will bring new chassis designs into attestation from the ground up, defining what is measured, how component identities are sealed during manufacturing, and how they are verified after deployment. And you will build the services that turn those measurements into one authoritative answer to whether every machine in our data centers is in a known good state.

The right candidate will have a successful track record of securing compute platforms and building end-to-end security solutions. You should have a strong mix of educational and practical experience, be comfortable working from silicon and firmware up through the services that verify them, and have a passion for diving head first into challenging problems.

You will work cross-functionally with security teams throughout Apple as well as system software, platform design, SOC architects, manufacturing, data center operations, and cloud services teams to develop and integrate best in class hardware, software, and services. You will be responsible for the security of the platform that powers the next generation of data centers.

This position requires someone with strong technical strengths and an enthusiastic drive to secure systems by showing how they can be broken. Our controls have to hold against a remote attacker and against someone with physical access to a chassis who wants a modified machine to look genuine.

We are a dynamic, growing team spanning many disciplines, and we expect members to be willing to step out of their comfort zones to contribute to team objectives. A successful engineer in this role is one that is happy to have a wide breadth of influence as well as deep focus areas in the context of a rapidly evolving project.

Minimum Qualifications

7+ years of experience.
Proficiency in C/C++.
Background in developing and maintaining code security-critical codebases.
Understanding of applied cryptography, cryptography hardware, and key management, including PKI and HSM-backed certificate issuance.
Experience with mutual authentication and hardware-based attestation, including Secure Boot, firmware measurement, and challenge-response protocols.
Strong understanding of hardware/software interactions and low-level software.

Preferred Qualifications

Background in definition and design of secure embedded systems, and in bringing new hardware platforms from manufacturing into production.
Experience with server component firmware, such as ARM SoC architecture, baseboard management controllers, system-management microcontrollers, and power delivery.
Understanding of past, current, and emerging security exploit types targeting low-level systems, including physical and insider attacks on data center hardware.
Experience building and operating production services that verify security posture across a large fleet and detect drift over time.
Experience with Swift, Objective-C, and Apple development tools.